ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Software: S0456×

24 examples

TechniqueUsed byProcedure example
T1010
Application Window Discovery
MalwareAria-body

Aria-body has the ability to identify the titles of running windows on a compromised host.

T1016
System Network Configuration Discovery
MalwareAria-body

Aria-body has the ability to identify the location, public IP address, and domain name on a compromised host.

T1025
Data from Removable Media
MalwareAria-body

Aria-body has the ability to collect data from USB devices.

T1027.013
Encrypted/Encoded File
MalwareAria-body

Aria-body has used an encrypted configuration file for its loader.

T1033
System Owner/User Discovery
MalwareAria-body

Aria-body has the ability to identify the username on a compromised host.

T1049
System Network Connections Discovery
MalwareAria-body

Aria-body has the ability to gather TCP and UDP table status listings.

T1055.001
Dynamic-link Library Injection
MalwareAria-body

Aria-body has the ability to inject itself into another process such as rundll32.exe and dllhost.exe.

T1057
Process Discovery
MalwareAria-body

Aria-body has the ability to enumerate loaded modules for a process..

T1070.004
File Deletion
MalwareAria-body

Aria-body has the ability to delete files and directories on compromised hosts.

T1071.001
Web Protocols
MalwareAria-body

Aria-body has used HTTP in C2 communications.

T1082
System Information Discovery
MalwareAria-body

Aria-body has the ability to identify the hostname, computer name, Windows version, processor speed, and machine GUID on a compromised host.

T1083
File and Directory Discovery
MalwareAria-body

Aria-body has the ability to gather metadata from a file and to search for file and directory names.

T1090
Proxy
MalwareAria-body

Aria-body has the ability to use a reverse SOCKS proxy module.

T1095
Non-Application Layer Protocol
MalwareAria-body

Aria-body has used TCP in C2 communications.

T1105
Ingress Tool Transfer
MalwareAria-body

Aria-body has the ability to download additional payloads from C2.

T1106
Native API
MalwareAria-body

Aria-body has the ability to launch files using ShellExecute.

T1113
Screen Capture
MalwareAria-body

Aria-body has the ability to capture screenshots on compromised hosts.

T1134.001
Token Impersonation/Theft
MalwareAria-body

Aria-body has the ability to duplicate a token from ntprint.exe.

T1134.002
Create Process with Token
MalwareAria-body

Aria-body has the ability to execute a process using runas.

T1140
Deobfuscate/Decode Files or Information
MalwareAria-body

Aria-body has the ability to decrypt the loader configuration and payload DLL.

T1547.001
Registry Run Keys / Startup Folder
MalwareAria-body

Aria-body has established persistence via the Startup folder or Run Registry key.

T1560
Archive Collected Data
MalwareAria-body

Aria-body has used ZIP to compress data gathered on a compromised host.

T1568.002
Domain Generation Algorithms
MalwareAria-body

Aria-body has the ability to use a DGA for C2 communications.

T1680
Local Storage Discovery
MalwareAria-body

Aria-body has the ability to identify disk information on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.